Sr. Automation & Cybersecurity Engineer

Actus Consulting Group

Plano (TX)

On-site

USD 120,000 - 180,000

Full time

38 hours ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Actus Consulting Group seeks a Senior Automation & Cybersecurity Engineer to lead hands-on design, build, and scaling of automation powering the SOC. Own automated detection, enrichment, triage, and AI-assisted workflows to reduce analyst toil and strengthen incident response.

The ideal candidate combines scripting, API integration, SIEM/SOAR development, and cloud automation with practical cybersecurity judgment.

Qualifications

  • 6-9 years in cybersecurity engineering with 3-4 years in security automation or SOC engineering.
  • Strong proficiency with Python, PowerShell, APIs, cloud automation, and integration patterns.
  • Hands-on with enterprise SIEM/SOAR platforms; Microsoft Sentinel preferred.

Responsibilities

  • Design, build, and maintain automation for alert enrichment, triage, and incident response across SIEM/SOAR platforms.
  • Develop integrations using Python, PowerShell, APIs, and cloud services with robust error handling.
  • Collaborate with SOC and detection teams to improve workflows and reduce false positives.
  • Design AI-assisted workflows with human-in-the-loop approvals and auditable controls.
  • Mentor teammates and help establish reusable automation standards.

Skills

Python
PowerShell
APIs
SIEM/SOAR
Cloud automation
Automation design

Education

Bachelor's degree in Cybersecurity/IT/CS

Tools

Microsoft Sentinel
Defender/XDR
Azure Logic Apps
Tines
ServiceNow
Log Analytics
Confluence

Job description

Summary:

The Senior Automation & Cybersecurity Engineer is a hands-on technical leader responsible for designing, building, and scaling automation that powers the Security Operations Center (SOC). This role owns automated detection, enrichment, triage, response, and AI-assisted workflows that reduce analyst toil, improve signal quality, and strengthen incident response.

The ideal candidate combines strong engineering fundamentals - scripting, API integration, SIEM/SOAR development, and cloud automation with practical cybersecurity judgment. They will partner with detection engineers, incident responders, analysts, and platform owners to convert repeatable processes into reliable, governed automation and safely pilot emerging AI and agentic capabilities.

Essential Functions:
  • Design, build, and maintain automation for alert enrichment, correlation, triage, incident response, and case handoffs across SIEM/SOAR platforms such as Microsoft Sentinel, Defender/XDR, Azure Logic Apps, Tines, ServiceNow, Log Analytics, and Confluence.
  • Develop integrations and tooling using Python, PowerShell, APIs, and cloud-native services, with production-quality error handling, monitoring, documentation, and reuse.
  • Collaborate with detection engineers, incident responders, and SOC analysts to identify automation opportunities, improve detection workflows, reduce false positives, and streamline analyst operations.
  • Design AI-assisted and agentic workflows for enrichment, investigation, summarization, and decision support, ensuring human-in-the-loop approvals, auditability, and measurable quality controls.
  • Partner with security, infrastructure, platform, compliance, and risk teams; participate in code/design reviews; mentor others; and help establish reusable automation standards and patterns.
Competencies:
  • Develops scalable and reliable security automation that improves SOC efficiency and operational effectiveness.
  • Applies sound cybersecurity judgment to design secure, governed, and auditable automation and AI-assisted workflows.
  • Collaborates effectively with cross-functional teams to improve detection, response, and operational processes.
  • Continuously improves workflows by reducing manual effort, false positives, and analyst workload through automation.
  • Provides technical leadership through mentoring, code reviews, and the promotion of engineering best practices.
  • Evaluates and implements emerging technologies, including AI capabilities, to enhance security operations while maintaining human oversight.
Requirements
  • 6-9 years of cybersecurity engineering experience, including 3-4 years focused on security automation, SOC engineering, SIEM/SOAR development, or similar work.
  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related field (preferred)
  • Strong proficiency with Python, PowerShell, APIs, cloud automation, and production-grade integration patterns.
  • Hands-on experience with enterprise SIEM/SOAR platforms, Microsoft Sentinel preferred, and working knowledge of Microsoft Defender/XDR, Azure Logic Apps, or similar technologies.
  • Solid understanding of threat detection, logging pipelines, alert tuning, incident response workflows, and operational metrics.
  • Excellent problem-solving, documentation, communication, and collaboration skills, with a track record of delivering reliable automation in production.
Preferred Qualifications:
  • Experience with Tines for SOC automation and agentic workflow orchestration.
  • Experience building an Agentic SOC using LLM/AI agents for enrichment, investigation, triage, response, and feedback-driven evaluation.
  • Experience with detection-as-code, CI/CD, MITRE ATT&CK, ASIM schemas, Sigma rules, behavioral detections, or observability pipelines.
  • Hands-on experience with LLMs, intelligent agents, AI/ML-assisted security tooling, prompt design, or agent evaluation.
  • Relevant certifications such as Microsoft Cybersecurity Architect, GIAC Security Automation, or Azure Security Engineer Associate.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Automation & Cybersecurity Engineer
Senior Automation & Cybersecurity Engineer

Cinter Career Services, LLC • Plano (TX)

On-site
USD 130,000 - 180,000
Senior Automation & Cybersecurity Engineer
Senior Automation & Cybersecurity Engineer

cinter • Plano (TX)

On-site
USD 120,000 - 160,000
Senior Automation, Cybersecurity Engineer
Senior Automation, Cybersecurity Engineer

Jobtailor • Plano (TX)

On-site
USD 140,000 - 190,000
Sr. Automation & Cybersecurity Engineer
Sr. Automation & Cybersecurity Engineer

Toyota Tsusho Systems US, Inc. • Plano (TX)

On-site
USD 120,000 - 180,000
Senior Automation & Cybersecurity Engineer
Senior Automation & Cybersecurity Engineer

Cinter Career • Plano (TX)

On-site
USD 140,000 - 190,000
Senior Security Automation, SOAR Engineer
Senior Security Automation, SOAR Engineer

Jobtailor • Colorado

On-site
USD 140,000 - 170,000
Senior AI-Driven Security Automation Engineer
Senior AI-Driven Security Automation Engineer

Actus Consulting Group • Plano (TX)

On-site
USD 120,000 - 180,000
Sr. SOC Analyst
Sr. SOC Analyst

HW3 • Village of Great Neck (NY)

On-site
USD 130,000 - 170,000
SOC Engineer
SOC Engineer

TENEX.AI • United States

On-site
USD 100,000 - 130,000
Senior AI-Driven SOC Automation Engineer
Senior AI-Driven SOC Automation Engineer

Cinter Career • Plano (TX)

On-site
USD 140,000 - 190,000